Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
Law360, Expert analysis: The financial sector faces a constantly evolving landscape of cyber threats, further amplified by the rapid advancement of technologies like artificial intelligence (AI). Simon Onyons, managing director, and Nebu Varghese, senior director, at FTI Consulting Inc explore implications for financial sector institutions, analyse key changes introduced by the updated TIBER-EU framework, provide practical guidance on navigating the complexities of DORA compliance, and highlight the importance of a unified approach to cybersecurity testing in the face of evolving threats.
CHECKLISTS
ARCHIVED: This Checklist has been archived and is not maintained. Cybersecurity is the infrastructure of technologies, processes and practices used to protect networks, data and technology from unauthorised access. Cybersecurity measures adopted by organisations need to guard against breaches motivated by malicious intent (whether that is financial crime, cyber terrorism, industrial espionage, hacktivism or state-sponsored attacks), or through unfortunate incidents. The ability of malicious third parties to successfully penetrate and damage an organisation is growing. This means that the security of a financial services firm’s network and the safety of its data is increasingly important, and cyber security is the focus of a number of regulatory and industry initiatives. Key dates and publications—2026 Date Description 15 May 2026 BoE, the FCA and HM Treasury (HMT) issued The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience. Key dates and publications—2025 Date Description 3 December 2025 As part of its Fundamental Elements Series, the G7 Cyber Expert Group released G7 fundamental elements
NEWS
The European Commission has launched a call for evidence on an initiative titled ‘Towards European open digital ecosystems’, seeking feedback on how to strengthen the EU open-source sector and reduce dependence on non-EU digital technologies. The initiative aims to support EU technological sovereignty, competitiveness and cybersecurity and will inform a Commission communication to the European Parliament and the Council expected in Q1 2026. The call for evidence closes on 3 February 2026.
PRECEDENTS
This data breach panic sheet gives tips on what to do and what not to do in the immediate aftermath (first 24 hours) of a data security breach. It reflects requirements of the GDPR itself and follows the preliminary stages of a process suggested in the UK Information Commissioner’s Office’s (ICO) guidance on data security breach management (subsequently withdrawn, and although not directly applicable in Ireland provides useful guidance and tips). There is not an equivalent set of guidance published by the Data Protection Commission (DPC) on data breach process. The DPC have published guidance on requirements relating to the data breach notification to the DPC and data subjects, which is reflected in this note and hyperlinked. On discovering a data breach, the first thing you should do is assemble a data breach team comprising the various people within your organisation who are best placed to respond to the breach (as described above). Having assembled your data breach team, you can then: • conduct a preliminary assessment of the breach • contain the data breach and (so far as reasonably practicable) recover, rectify
NEWS
This week's edition of EU Law weekly highlights includes the publication of the Data Protection Authorities’ AI framework statement, the first report on the cybersecurity and resilience of the EU’s telecommunications and electricity sectors, and the European Commission coordinating action by national consumer protection authorities against Meta on ‘pay or content’ model. The highlights also include analysis of the NIS2 draft Implementing Regulation on technical and methodological requirements and significant incidents, and news of the re-elected Commission President’s vision for her new mandate.
NEWS
The Financial Conduct Authority (FCA) has published a speech by its CEO, Nikhil Rathi, on liquidity, risk and how capital markets can drive economic growth and development in volatile times. Rathi discussed the causes of increased disruption in the financial system, and called for a number of changes, including a shift from reactive to proactive regulation, a new mindset towards risk, and investment in infrastructure, particularly around technology and cybersecurity.
PRECEDENTS
1. Data breach team Damage limitation is a priority immediately following a security breach. You will need a team of people to manage the data breach. What should you do? ☐ Assemble a data breach team, including your data protection officer (DPO) and/or data protection manager (DPM) (if you have one), head of legal/compliance, head of IT and head of HR (if employee data is involved). ☐ Appoint someone to lead the team (preferably not your head of IT). 2. Preliminary notifications Your first instinct may be to tell affected individuals and regulators about the breach, but you need more information before you can decide whether this is necessary or desirable. The time limit for notifying the Information Commissioner’s Office (ICO) under the UK General Data Protection Regulation (UK GDPR) is 72 hours from becoming aware of the breach and the UK GDPR Recitals suggest you should notify the ICO first before communicating with data subjects. Your focus during the first 24 hours should be on containment and recovery. What should you do? ☐
NEWS
MLex: The European Commission will issue guidelines on how the EU AI Act interacts with other EU laws such as the EU GDPR, product safety legislation, platform regulations and copyright rules only around the third quarter of 2026—meaning just before or just after the law’s high-risk obligations will take effect. The delay adds pressure on the commission as it weighs whether to pause the EU AI Act’s high-risk requirements.
NEWS
MLex: A German court decision to uphold a fine against leading property company Deutsche Wohnen over a data privacy breach has been applauded by Berlin’s data watchdog despite a significant reduction in the penalty following a long legal battle. A Berlin regional court slashed the fine to €900,000 from €14.5 million this week, saying the company had cooperated and worked to find a technical solution and build a compliant system.
NEWS
Law360: On 3 June 2024, the European Data Protection Supervisor issued its first guidelines regarding generative Artificial Intelligence (AI).
NEWS
MLex: Meta Platforms, Microsoft, Google and X have all suspended the training of generative AI models in the EU over personal data protection concerns, and they are hoping that watchdogs there will soon provide legal clarity on how the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) applies to model training. Until European data protection authorities reach a consensus, particularly over the use of 'legitimate interest' as a legal basis for data processing, tech companies will stay away.
PRACTICE NOTES
This tracker sets out key dates and information relating to proposed changes to privacy and electronic communications laws in the EU. It includes consultations, discussion drafts, progress reports and opinions related to Directive 2002/58/EC, the EU ePrivacy Directive. Reforms to the current EU ePrivacy Directive have been underway for some time in the EU, with the proposed ePrivacy Regulation intended to bring a more harmonised approach across EU Member States. The proposed Regulation covered privacy and related aspects of online communications, direct marketing, analytics, spamming and cookies. Its scope was wider than the ePrivacy Directive and it would have applied to all electronic communications service providers in the EU, as well as non-EU providers providing such services to EU residents. That includes ‘over-the-top’ communications providers (such as WhatsApp or Facebook Messenger), as well as organisations providing customer Wi-fi access and machine-to-machine communications. However, the proposal for an ePrivacy Regulation was withdrawn in February 2025 (see: LNB News 12/02/2025 67). Latest EU position on the ePrivacy reform After four years of difficult negotiations, the Council of the EU reached